Lightning-address usernames are not unique: transport create/update skip the check and the schema has no constraint #4
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Username uniqueness is enforced only by
check_username_exists(views_api.py:103-109), called only from the HTTP create/update handler (:198-207).handle_lnurlp_create(transport_rpcs.py:44-51) andhandle_lnurlp_update(:86-105,"username"is in_MUTABLE) never call it.migrations.py:155addsusername TEXTwith no UNIQUE index, andget_address_data(crud.py:75-79) is afetchonewith no ordering. Once two rows share a username,/.well-known/lnurlp/<name>resolves to an arbitrary one of them: a second account can registeraliceover the transport and receive payments addressed toalice@domain, and zap attribution for the address breaks. Even HTTP-only, check-then-insert is racy under concurrent creates.Fix direction: call the shared validator (incl. the uniqueness check) from the transport handlers; add a fork migration creating a UNIQUE index on
lnurlp.pay_links(username)(partialWHERE username IS NOT NULLon Postgres; SQLite already allows multiple NULLs) so both the transport gap and the HTTP race are closed at the schema. Test: second create with a taken username fails over both surfaces.Found during reforge run #1 (sandbox lnurlp#10).